Live data from Hacker News

Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

ccc.de

1–10 of 166 posts

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#3
I realize that to some it may appear as obvious, but quite often the obvious is overlooked as people respond to the hastily promoted propaganda relative to a system and become emotionally entangled in it instead of holding to reason.

Having prefaced my response with the above clarification, such an outcome should be expected rather than being unexpected. There's no such thing as a totally secure and uncompromisable system. Any system can be compromised. Where there's a system, there's a way to compromise it.

When all is said and done, what can reasonably be expected is a system that's as secure as it can be reasonably made and a genuine effort to patch vulnerabilities as quickly as humanly possible.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#4
post #2

"The by far most expensive part of the iris biometry hack was the purchase of the Galaxy S8 smartphone."

and " Ironically, we got the best results with laser printers made by Samsung"

You can tell they really had fun with this!

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#6
Whilst it's certainly valuable to make people aware of the limitations of the security systems we use, this shouldn't really come as a surpre. If someone is close enough and motivated enough to take a high-res photo of your face just to access your mobile device, they're also probably close enough to film you typing in your passcode - sure, you might do that less often, but for an average user are either of those things a real concern? The security model hasn't really been "broken" because if someone steals my phone they don't have access to the device by default.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#7
„But biometric authentication does not fulfill the advertised security promises“

This is completely out of context. For the average smartphone user Iris-Recognition on a phone (just like touch-ID) VS pin-disabled on the phone is a huge step forward.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#8
> The Samsung Galaxy S8 is the first flagship smartphone with iris recognition.

That's not quite true, Lumia 950, Lumia 950 XL and HP Elite x3 came out a lot earlier than the Galaxy S8 and all of them use iris recognition (still undefeated, by the way)

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#9
Based on the write-up, Samsung has lower quality Iris recognition than could be written by an undergrad in a few hours. I say that, having done so.

Most obviously, the system should not tolerate a constant-size pupil, ever. The pupil has micro-dilations around twice per second, and your system is really terrible if you don't verify that changing diameter.

Also, multi-spectral is a pretty good test, though I don't know enough about the capabilities of the S8 camera to know if that's feasible (shouldn't be that hard.) Capturing the patterns of the iris at 500, 800, and 1200nm results in three templates that are quite different from another.

CCC were able to do this for about the cost of a S8. I would say this is one of the rare situations where defeating the attack would have been even cheaper. It's that simple a programming exercise.

Re: Chaos Computer Clubs Breaks Iris Recognition System of the Samsung Galaxy S8

#10
post #6

Whilst it's certainly valuable to make people aware of the limitations of the security systems we use, this shouldn't really come as a surpre. If someone is close enough and motivated enough to take a high-res photo of your face just to access your mobile device, they're also probably close enough to film you typing in your passcode - sure, you might do that less often, but for an average user are either of those thi…

With a 4k camera and decent light conditions that could be possible in public space. Whereas you can avoid entering your passcode in public spaces (or shield it well enough).

It shows again that for people with very valuable data (where others would spend significant amounts of money to get data), passwords remain the only secure way.

Post reply on HN